Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2021-45007: CVE-2021-45007/README.md at main · AS4mir/CVE-2021-45007

Plesk 18.0.37 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows an attacker to insert data on the user and admin panel.

CVE
#csrf#vulnerability#git

Permalink

Cannot retrieve contributors at this time

CVE-2021-45007

Cross-Site Request Forgery

Cross-Side Request Forgery (CSRF)

Affected product and version: Plesk CMS 18.0.37

Severity: High

Impact: Submit requests with attacker information

Description: CSRF could let the attacker to submit requests because there isn’t any CSRF_token protection sent with requests to server.

Steps to reproduce:

  1. Login and try to submit any request

  2. Capture the request with burp suite image

  3. Will note that there isn’t any token protection sent with request to server

  4. Write simple html exploit to submit request image

  5. Open it in browser image

  6. Submit the request image

  7. Will find that your data are submitted successfully image

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907